An update for rh-nodejs6-nodejs-qs is now available for Red Hat SoftwareCollections.

Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

The qs module for Node.js is a querystring parser that supports nesting andarrays with a depth limit.

The following packages have been upgraded to a later upstream version:rh-nodejs6-nodejs-qs (6.2.3). (BZ#1485934)

Security Fix(es):

* It was found that ljharb's qs module for Node.js did not properly parsequery strings. An attacker could send a specially crafted query thatoverwrites the resulting object's prototype properties (such as toString()or hasOwnProperty()), resulting in a denial of service when the overwrittenfunction would be executed. (CVE-2017-1000048)

4. Solution:

For details on how to apply this update, which includes the changesdescribed in this advisory, refer to: